Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

PaddyNewman

Members
  • Posts

    394
  • Joined

  • Last visited

Reputation

740 Excellent

About PaddyNewman

Personal Information

  • Interests
    Gaming / Custom PCs / Motorcycling / Musical Instruments

Employer (optional)

  • Company Represented
    London Grid for Learning (LGfL)

Recent Profile Visitors

2,590 profile views
  1. Weirdly I just threw it through a bind server with nxdomain for the 2 icloud URLs and I have really upset the device. Will test again when I can grab the iPhone but I got no bypass with the relay showing as unavailable and the connectivity assist on, my logs show it hitting the filtering system multiple times rather than once so the browser didn't attempt to go round the back this time. I need to hit it harder and see what happens, I hate it when its not consistent.
  2. Exactly what I was seeing. This is not great. I would note though... I would just be on 4G as a student anyway so its sort of always been a problem. The biggest one here is the illusion of connected to school = safe and filtered. Very much an annoyance.
  3. Mine is the same, tried browsing to various sites, 888, Surfshark etc. With the toggle on, I get a deny log (In Netsweeper, not Smoothwall but at this point if feel its going to be vendor agnostic) then browser just throws out of 4G. I only have TCP 80 443 and DNS to our DNS, I operate on a very locked down firewall, but its using 4G to dip out.
  4. Looking at this from an iPhone perspective as my iPad has no cellular, its sending the request through 4G looking at the mobile data... Wonderful move Apple. Turning it off breaks things as expected and no 4G data appears to take place, but sending it via Connectivity Assist just offloads the failure to 4G and boom, connected. Can only see the fix being MDM payloads which aren't great for BYOD as its not your device to manage. I havent tried decrypted traffic yet, but will assume a similar pattern of can't get there, try the other way. The other amazing move by Apple - "Connectivity Assist is on by default", much appreciated.
  5. Interesting. Ive just got ios27 - will give this a whirl. I would presume you block all other DNS regardless?
  6. I do a bit of friends and family support, because my family are very 1 finger typing style. Rustdesk is now hosted on my local microserver and I believe its free commercially. Whether it does everything.... but its free and allows unattended. Im just a remote in and fix it jobby but also let's me get to my machine from my mobile thru starlink, only reason I touched it.
  7. I won't get too involved as it makes me sorta angry, yearly checks feel like a tick box for gov to say 'well we did ask' and schools to absolve themselves. Checks should be done often. The Internet isn't sitting still. People make mistakes, human error causes open holes. My boiler is serviced yearly, my car MOT is yearly, my teeth are checked 6 monthly... Kids safety is more important than all of those, but check their safety net once a year, good job /s Honestly if I was in schools rather than ISP side, machine in every vlan and capable of being on every individual policy, constantly checking known endpoints, alert for any anomalies, weekly audit of filtering changes, termly firewall checks. Costs a little setup but you have the answers whenever you are questioned. With DSLs supposed to be taking control of whats allowed, but maybe tech level not so high, the risk of changes going squiffy is high. I know some schools check often, I know some haven't made a single change in 3 years and just expect it to keep working. Im genuinely scared at some points. I'll now retire to my hole and rest! (Obviously its my personal view, not the company view...)
  8. Forgive me as I haven't touched a Smoothwall in years and even then, it was light. Are you just sending items to the Smoothwall for filtering and giving that as the gateway for clients? VLAN100 should be tagged for it to pass to the Smoothwall if so, but this all sounds odd to me. Your next hop is in the same subnet, so just changing gateway could bypass no? I would probably set it up differently but I really am struggling to draw this out on paper,presumably due to my lack of SW knowledge. How does the sonicwall connect to the smoothwall, 1 physical port with a trunk loaded with vlans? I feel it could be simplified but like I say, struggling to work out the actual topology.
  9. Let me know your school and I will check your settings
  10. Multicast streaming? Different wifi/vlans? No mDNS repeater. Only thing thats ever really scuppered stuff was that when I was doing fun stuff at home with casting.
  11. Our "HomeProtect" offering, its Netsweeper under the hood. Blocks correctly iPad browser only mode and full device filtered iPad mode.
  12. Had to test because that would be concerning if it was that easy... For my local filter, ipad, bitly to tiktok, it redirected and I got blocked. On my raw home feed with our cloud filter on ipad, I get the same, redirects to tiktok.com and blocked. using "bit.ly/4bksbnG" as my test.
  13. To not derail this too much as this is definitely something SBB can handle, but for our homeprotect stuff, happy to hear some ideas/what to do different via DM or support case
  14. Same as above theres a few ways, I have some form of this in a doc somewhere from a recent customer call.
×
×
  • Create New...